The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack
https://wpscan.com/vulnerability/1dc7caac-a36e-4313-a8be-c6b13e564924/